I already uploaded a sensitive PDF to AI. What now?
The file is already sent. Here's the triage that still works, and the steps that only feel productive.
It usually hits a few seconds too late. The answer comes back, it's genuinely useful, and then you notice what you actually dropped in. The client list. The salary column. A page you never meant to attach.
You can't unsend it. Worth accepting that fast, because everything useful happens after.
First, find out what you actually sent
Most people are fuzzy on this part. You remember the page you cared about, not the eleven pages stapled behind it, the author name sitting in the file properties, or the comment somebody left in the margin three revisions ago.
Open your local copy and look properly. Your exposure was defined by the file, not by the question you asked. Remove PDF Metadata shows you what was riding along in the document properties, and Strip Hidden Content surfaces attachments and embedded pieces you may not have known were in there. Both run locally, so auditing the file doesn't repeat the mistake.
Sort it into two piles
Not every accidental upload is an incident, and treating them all the same wastes the urgency you might actually need.
Awkward. An internal draft, your own notes, an ordinary contract nobody would pay to read. Unpleasant, low consequence.
Actionable. Credentials or API keys. Other people's personal data. Health or legal records. Anything covered by a contract, an NDA, or a regulation. This pile has a clock on it.
Do the things that still work
The split below is the honest one. Some of it is yours to fix, and some of it left your hands the moment you hit send.
Delete the conversation and the file. Do it, but know what it buys you. Deleting from the interface removes it from your view. It isn't a guarantee of instant erasure everywhere, because providers keep backups, abuse-review copies, and their own retention windows.
Check the training setting. Turning off data reuse is worth doing. It's also usually forward-looking. Flipping that switch today doesn't reach back and pull yesterday's upload out of anything.
Rotate any secret that was in the file. This is the one piece that's fully in your control and fully effective. A password inside a PDF is a password that needs changing. Same for API keys, tokens, and recovery codes. Do this before you finish reading.
If it wasn't your data, tell someone
This is the step people skip, and it's usually the one that matters. If the file held client, patient, employee, or partner information, somebody in your organization needs the facts to decide what happens next.
I'm not going to tell you whether it counts as a reportable breach. That depends on your jurisdiction, your contracts, and what was actually in the document. What I can say is that the person who decides needs to know, and the uncomfortable ten minutes now is smaller than the discovery later.
Four things that don't help
- Asking the model to forget. It'll often agree. That's a conversational reply, not a data control.
- Starting a fresh chat. A new thread doesn't retract the old one.
- Deleting your own evidence. If a compliance process might start, the record of what was sent and when is something the process needs.
- Assuming a setting applied retroactively. Whatever was configured at upload time is what governed that upload.
Make the next one smaller
The fix isn't avoiding AI with documents. It's sending less of the document. Pull out the pages that answer your question, strip what the question doesn't need, and check the copy before it goes anywhere. If you want the full version of that, see the checklist for sensitive PDFs.
One honest note to end on
Most of these end quietly. A summary of an unremarkable contract sits in a log somewhere and nothing ever comes of it. The real cost usually isn't dramatic. It's that you don't get to know, and that uncertainty is exactly what's worth avoiding next time.